Third Party Index

Snapshot 49943

Document
Security page
URL
https://ahasend.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
586656 bytes
SHA-256 (raw)
7b6b40f31491bca1b97303713822a175f9b57bfa10c0a98bd761e1e22d0ae906
SHA-256 (normalized text)
243faaf8f48c0aff6e8cd9a8175931b128a0b99cc3095a4a9f8a9505cf3c9e1d

Normalized text

Scripts and page chrome removed; this is what change detection compares.

WHERE AHASEND RUNS
Five sites.
One network.
A core ring across Falkenstein, Nuremberg and Helsinki, with Oslo and Sofia uplinked into it.
5EU / EEA sites
4Countries
GDPR compliantHosted in EuropeISO 27001 · in progress
SECURITY FEATURES
Built to keep your email and your data safe
Every account gets the same security features, on every plan.
Two-factor authentication, enforced
Protect your account with TOTP-based 2FA, and require it for your whole team with account-wide enforcement.
Learn more
Single sign-on
Log in through your own identity provider with OpenID Connect SSO, including PKCE and multi-domain support.
Learn more
Scoped API keys
Restrict every API key to specific domains and granular permissions, so a leaked key for one service cannot touch anything else.
Learn more
IP allow lists
Lock any API key to the IPv4/IPv6 addresses or CIDR ranges you specify. Changing an allow list requires re-authentication and alerts your admins.
Learn more
Signed webhooks
All webhooks follow the Standard Webhooks specification with HMAC signatures and timestamps, so your endpoints can verify every event.
Learn more
Sandbox mode
Test your full integration, including bounces and webhooks, without a single real email leaving the platform.
Learn more
You decide how long we keep your data
Message metadata for 1 to 30 days, full message content anywhere from 30 days down to zero.
Learn more
Our infrastructure is
the security feature
Most email providers rent their infrastructure and inherit its risks. We took the opposite route. Owning the full stack means we control patching, hardening, and monitoring down to the metal. The answer to "where does my email data live?" is one sentence: in Europe, on machines we own.
Own hardware, own network
European datacenters, on our own network with our own ASN. No US hyperscaler underneath.
No hidden subprocessors
Nothing sits between you and the mail server, and no foreign jurisdiction has a legal claim on your data in transit.
Learn more
Monitored down to the metal
We control patching and hardening; delivery is TLS-secured and our current status is always public at status.ahasend.com.
Where your data lives
All email content, message data, metadata, logs and analytics are stored in the EU, on hardware we own in our core sites in Falkenstein, Nuremberg and Helsinki. Our Oslo and Sofia sites are delivery nodes only: mail can pass through them on its way to the recipient, nothing is stored there. Oslo is why we say EU/EEA rather than EU. Two exceptions, in the interest of full transparency: (1) The nameservers for ahasend.com itself are currently at Cloudflare. That affects DNS resolution of our website, not your email data. A migration is planned. (2) An optional US node exists. It is strictly opt-in and never used unless you explicitly choose it.
COMPLIANCE
Compliance, in writing
GDPR
AhaSend is a European company under European law. Our Data Processing Agreement is public, ready to sign, and doesn't hide a US parent behind an EU letterbox.
Learn more
CSA Certified Sender
AhaSend is certified by the Certified Senders Alliance, the sender accreditation programme run with eco and the German mailbox providers.
Learn more
ISO 27001
Our certification audit is scheduled for September 2026, and we're doing it transparently: our Trust Center shows the current status, our controls, and our policies as they stand today, not after a certificate makes it look effortless.
Learn more
Subprocessors
The full list of subprocessors is published in our DPA: Hetzner, DA International Group Ltd, and Blix. Owning our infrastructure means there's very little to disclose.
Learn more
Responsible disclosure
Found a vulnerability? We have a published responsible disclosure policy and we respond fast.
Learn more
Questions a security review will ask
All email content, message data, metadata, logs and analytics are stored in the EU, in datacenters on hardware AhaSend owns and operates in Germany and Finland. Mail in transit may pass through our delivery nodes in Norway and Bulgaria; nothing is stored there. No US hyperscalers underneath. Our optional US node is strictly opt-in and never used unless you explicitly choose it.
Still have questions?
Check our documentationContact support
See for yourself
The Trust Center has the documents. The free tier has 1,000 emails a month. Your security team can read while your developers send.
Visit our Trust Center